Maturity assessments and gap analysis: how to actually raise your security and data protection posture
A practical guide to using maturity assessments, target setting, and gap analysis to move data protection and cybersecurity from ad hoc to managed, with the improvement loop that makes it stick.
By André Årnes and Magdalena Goralczyk
Most organisations know roughly where their weak spots are. What they struggle with is turning that hunch into a defensible, measurable programme of improvement that a board, an auditor, or a regulator will accept. A maturity assessment is how you replace "we think we're reasonably good at access control" with "we are at Level 2, our target is Level 3, and here is the dated plan to close the gap."
This guide walks through the full loop: assess where you are, set where you want to be, measure the gap, and close it. It applies to both cybersecurity and data protection, and it is the backbone of how Pritect helps teams improve rather than just record.
Why a maturity model beats a checklist
A checklist answers a binary question: is the control present or not. That is useful for a point-in-time audit, but it tells you nothing about how well something is done, and it gives you nowhere to go once every box is ticked.
A maturity model answers a better question: how consistently, how measurably, and how durably is this control operating. That turns governance into something you can improve year over year, and it matches how supervisory authorities and frameworks increasingly think, from NIS2's risk-management expectations to the ICO's Accountability Framework.
The maturity scale
Pritect scores cybersecurity controls on a six-point scale, from 0 to 5. Each level has a clear, evidence-based definition so two different assessors reach the same score.
| Level | Name | What it means |
|---|---|---|
| 0 | Not Implemented | No control in place, or no evidence one exists |
| 1 | Ad Hoc | Initial or informal effort, little documentation |
| 2 | Developing | Documented intent, but inconsistent execution |
| 3 | Defined | A repeatable process with evidence of consistent execution |
| 4 | Managed | Measured and managed, with coverage reporting |
| 5 | Optimised | Continuously improved, with independent assurance |
Level 3 (Defined) is the sensible default target for most controls: a documented, repeatable process that actually runs. Levels 4 and 5 are where you invest selectively, on the controls that matter most to your risk profile.
What gets assessed
For cybersecurity, the assessment is built on the Pritect Cybersecurity Framework, which organises 100+ controls into 16 domains, including governance and compliance, identity and access management, asset management, cryptography, monitoring and detection, incident management, supply chain, and AI security. For data protection, the same maturity approach aligns to the ICO Accountability Framework's domains.
The point of the domain structure is that you do not get one blurry overall number. You get a profile: strong on identity, weak on supply chain, average on monitoring. That profile is what makes the gap analysis actionable.
Three ways to assess, depending on how much rigour you need
Not every assessment needs to be audit-grade. Pritect offers three modes so the effort matches the purpose:
- Self-assessment: a quick baseline. No evidence required, no approver. Good for a first read or an internal pulse check.
- Evidence-based: evidence uploads are encouraged against each answer, but not blocking. The right level for an ongoing internal programme.
- Auditable: evidence is mandatory per control and an assigned approver signs the assessment off. This is the mode you run when the result has to stand up to an external auditor or regulator.
Setting a target
A score on its own is just a measurement. It becomes a goal when you set a target. In Pritect you set an overall target maturity (Level 3 by default) and then override it per domain, because your ambition for identity and access management is probably higher than for, say, on-premise management if you are mostly cloud.
Targets are versioned and run through an approval workflow, with a rationale recorded against each one. That matters because the target is a governance decision: leadership is agreeing what "good enough" means for this organisation, this year.
Gap analysis: the distance between now and the goal
Once you have a completed baseline assessment and a target, the gap is straightforward arithmetic done per domain:
Gap = target level − current score
Pritect bands the result so attention goes where it is needed:
| Band | Gap size | Reading |
|---|---|---|
| On target | 0 or below | Current maturity meets or exceeds the target |
| Minor | up to 0.5 | Close; a small push gets there |
| Moderate | 0.5 to 1.0 | A real gap worth a planned initiative |
| Significant | above 1.0 | Priority; likely needs dedicated effort and budget |
The output is a domain-by-domain view with the baseline score, the target, the gap, and its severity, plus summary statistics: your average gap, how many domains are on target, and how many sit in each band. Domains you mark Not Applicable are excluded from the averages rather than dragging your numbers down with phantom gaps.
Closing gaps is a programme, not a paragraph
The most common failure mode is a beautiful gap report that nobody acts on. Pritect treats each gap as the start of a tracked remediation action: a titled initiative with a priority, an owner, start and end dates, and the specific controls it addresses. Each action records its expected impact, for example lifting governance from 2.5 to 3.2, so you can forecast the maturity you will reach before you spend the effort.
The improvement loop
Put together, the four steps form a loop you run on a cadence, not once:
- Assess the current state, control by control, at the rigour level you need.
- Set or confirm the target, overall and per domain.
- Analyse the gaps, prioritising by severity and risk.
- Close the gaps through owned, dated actions, then re-assess.
Each turn of the loop produces a new baseline, so over two or three cycles you have something more valuable than any single score: a trend. "Our average gap fell from 1.3 to 0.4 over the year, and every Tier 1 domain is now at or above target" is a sentence a board understands and an auditor respects.
Reporting that lands
Because every score, target, and action lives on the same record, the reporting comes for free. Pritect generates board-ready maturity and gap reports: baseline versus target per domain, the priority areas, the remediation status, and the trend over time. The same data feeds the executive dashboards, so security and data protection maturity sit alongside the rest of your governance posture in one view, rather than in a slide someone rebuilt by hand the night before.
See the maturity model, target setting, and gap analysis in the Pritect cybersecurity suite.
The same maturity and gap approach runs in the data protection suite against the ICO Accountability Framework, so you can hold privacy and security to the same measurable standard.
Run the same maturity and gap loop across your data protection programme.
